CyberRota
Back to database

CVE-2021-47949

HIGH · CVSS 8.8 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-05-10 · Last synced: 2026-06-09

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2021-47949
Severity
HIGH
CVSS
8.8
EPSS
0.11%

Original NVD Description

CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint.